ROUTING
The tier is set by the work, not by a default. High-authority judgment gets frontier capability; routine support runs cheaper.
BUILD IN PROGRESS · SEPTEMBER 2026
ADYX builds Charles — a control plane that sits between human intent and a fleet of models, agents, apps, machines, and real-world systems. Models are replaceable cognition. Charles owns the memory, the policy, the identity, the orchestration, and the evidence.
Most AI products begin with a model and add tools around it. Charles is built in the opposite direction. It begins with a durable, private representation of a person's world: what they have decided, what they are building, what they have delegated, what the system observed, and what it is allowed to do.
Compute and model weights are a market. Identity, memory, authority, and evidence are not — they compound, and they cannot be bought off the shelf. That asymmetry is the entire product strategy.
Immutable raw capture, structured records on top, provenance on every recall.
Authority and sensitivity classified before anything runs. Ambiguity fails closed.
Charles acts as Charles, on stated behalf — never as a silent impersonation.
A receipt proves resulting state and records what remains unobservable.
EVERY RESULT BECOMES FUTURE CONTEXT · EVERY CORRECTION BECOMES LAW
Every surface — phone, Mac, terminal, voice — is a disposable limb around one control plane. No limb owns a capability. Charles decides which model tier serves which work, and every action flows back as evidence.
MODELS AND COMPUTE ARE REPLACEABLE · THE CONTROL PLANE IS NOT
The tier is set by the work, not by a default. High-authority judgment gets frontier capability; routine support runs cheaper.
Sensitive content is confined to an approved vendor regardless of price. Privacy is a constraint, not a preference.
Cost, provenance, privacy, and correctness are read off a production usage ledger — not estimated.
Every unit of work is classified by authority and sensitivity before anything runs, and every result must survive an adversarial pipeline before it becomes a receipt. No single agent can author, approve, and verify its own work.
SMALL DECISION SURFACE: QUESTION · OPTIONS · RECOMMENDATION · EVIDENCE
APPROVED WORK ENTERS AN ADVERSARIAL PIPELINE BEFORE IT COUNTS
Outbound communication uses Charles's own identity, names that it acts on its principal's behalf, passes recipient and content gates, and writes an audit record. Money-moving requests are refused structurally, not by convention.
"The command ran" is not proof. Charles attempts to prove the resulting state, records what remains unobservable, and files both as canonical evidence that later work can rely on.
Charles is not a finished commercial product. Some limbs are live, some are working prototypes, and deeper orchestration remains staged. The durable architecture and the operating laws are the part built most deliberately.
Automatic cross-provider continuation is an active design and build area, not a deployed claim. A safe handoff must start a fresh successor from verified durable task state, fence stale workers, and produce an acceptance receipt. It cannot pretend one vendor's live conversation moved seamlessly into another.
A fully local core is in the same category: partly live, not claimed. The reconstitution test is the bar — any laptop, app, or model is disposable, and the mind is rebuildable from durable state.
STATED PLAINLY BECAUSE THE ALTERNATIVE IS A DEMO, NOT A SYSTEM
My answer is the mind, the policy, and the proof. I'm sharing this with people building in the same direction — not as a product claim or a pitch, but as a technical conversation I'd like to have.